Impact
GitHub Enterprise Server has a UI misrepresentation flaw that enables an OAuth application to obtain the manage_runners:org permission without that scope appearing on the consent screen. By creating such an application and directing a user to authorize it, an attacker can gain unintended control over an organization’s runners. This violation, classified as CWE‑451, allows the attacker to add, change, or delete runners, potentially compromising CI/CD pipelines. The issue impacts all releases before 3.22 and has been resolved in 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, and 3.16.20.
Affected Systems
All GitHub Enterprise Server releases before version 3.22 were affected. The vulnerability was fixed in releases 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, and 3.16.20. Administrators should upgrade to one of these patched releases.
Risk and Exploitability
The CVSS score is 4.8, and the EPSS score is below 1%. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a human victim to approve a deceptive OAuth application, typically through social engineering. The likely attack vector is inferred to be a social engineering phishing‑like attack where a user is persuaded to approve a malicious OAuth application. Once authorized, the attacker gains the ability to manage organization runners, which can be used to alter pipeline behavior and potentially disrupt CI/CD operations.
OpenCVE Enrichment